ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0373×

36 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareAstaroth

Astaroth collects the external IP address from the system.

T1027.002
Software Packing
MalwareAstaroth

Astaroth uses a software packer called Pe123\RPolyCryptor.

T1027.010
Command Obfuscation
MalwareAstaroth

Astaroth has obfuscated and randomized parts of the JScript code it is initiating.

T1027.013
Encrypted/Encoded File
MalwareAstaroth

Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys.

T1041
Exfiltration Over C2 Channel
MalwareAstaroth

Astaroth exfiltrates collected information from its r1.log file to the external C2 server.

T1047
Windows Management Instrumentation
MalwareAstaroth

Astaroth uses WMIC to execute payloads.

T1055.012
Process Hollowing
MalwareAstaroth

Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.

T1056.001
Keylogging
MalwareAstaroth

Astaroth logs keystrokes from the victim's machine.

T1057
Process Discovery
MalwareAstaroth

Astaroth searches for different processes on the system.

T1059.003
Windows Command Shell
MalwareAstaroth

Astaroth spawns a CMD process to execute commands.

T1059.005
Visual Basic
MalwareAstaroth

Astaroth has used malicious VBS e-mail attachments for execution.

T1059.007
JavaScript
MalwareAstaroth

Astaroth uses JavaScript to perform its core functionalities.

T1074.001
Local Data Staging
MalwareAstaroth

Astaroth collects data in a plaintext file named r1.log before exfiltration.

T1082
System Information Discovery
MalwareAstaroth

Astaroth collects the machine name and keyboard language from the system.

T1102.001
Dead Drop Resolver
MalwareAstaroth

Astaroth can store C2 information on cloud hosting services such as AWS and CloudFlare and websites like YouTube and Facebook.

T1105
Ingress Tool Transfer
MalwareAstaroth

Astaroth uses certutil and BITSAdmin to download additional malware.

T1115
Clipboard Data
MalwareAstaroth

Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries.

T1124
System Time Discovery
MalwareAstaroth

Astaroth collects the timestamp from the infected machine.

T1129
Shared Modules
MalwareAstaroth

Astaroth uses the LoadLibraryExW() function to load additional modules.

T1132.001
Standard Encoding
MalwareAstaroth

Astaroth encodes data using Base64 before sending it to the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareAstaroth

Astaroth uses a fromCharCode() deobfuscation method to avoid explicitly writing execution commands and to hide its code.

T1204.002
Malicious File
MalwareAstaroth

Astaroth has used malicious files including VBS, LNK, and HTML for execution.

T1218.001
Compiled HTML File
MalwareAstaroth

Astaroth uses ActiveX objects for file execution and manipulation.

T1218.010
Regsvr32
MalwareAstaroth

Astaroth can be loaded through regsvr32.exe.

T1220
XSL Script Processing
MalwareAstaroth

Astaroth executes embedded JScript or VBScript in an XSL stylesheet located on a remote domain.

T1497.001
System Checks
MalwareAstaroth

Astaroth can check for Windows product ID's used by sandboxes and usernames and disk serial numbers associated with analyst environments.

T1518.001
Security Software Discovery
MalwareAstaroth

Astaroth checks for the presence of Avast antivirus in the C:\Program\Files\ folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareAstaroth

Astaroth creates a startup item for persistence.

T1547.009
Shortcut Modification
MalwareAstaroth

Astaroth's initial payload is a malicious .LNK file.

T1552
Unsecured Credentials
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

T1555
Credentials from Password Stores
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

T1564.003
Hidden Window
MalwareAstaroth

Astaroth loads its module with the XSL script parameter vShow set to zero, which opens the application with a hidden window.

T1564.004
NTFS File Attributes
MalwareAstaroth

Astaroth can abuse alternate data streams (ADS) to store content for malicious payloads.

T1566.001
Spearphishing Attachment
MalwareAstaroth

Astaroth has been delivered via malicious e-mail attachments.

T1568.002
Domain Generation Algorithms
MalwareAstaroth

Astaroth has used a DGA in C2 communications.

T1574.001
DLL
MalwareAstaroth

Astaroth can launch itself via DLL Search Order Hijacking.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.